Description
A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. Impacted is an unknown function of the file /pages/pro_edit1.php. Such manipulation of the argument prodcode leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.
Published: 2026-09-14
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote SQL Injection
Action: Apply Patch
AI Analysis

Impact

The vulnerability arises in an unknown function within /pages/pro_edit1.php of itsourcecode Sales and Inventory System, where an attacker can manipulate the prodcode argument to inject arbitrary SQL, enabling unauthorized query modification or data disclosure. The impact is potential compromise of database confidentiality and integrity, allowing attackers to read, modify, or delete inventory records. The flaw is a classic SQL injection weakness, as indicated by the CWE classifications.

Affected Systems

This flaw affects the itsourcecode Sales and Inventory System, specifically version 1.0 as referenced in the description. No other versions or products are listed as affected, so only installations of this exact release are currently at risk.

Risk and Exploitability

The CVSS score of 5.3 denotes a moderate severity, and the EPSS score of less than 1% indicates a very low exploit likelihood at present. The vulnerability is not listed in the CISA KEV catalog, suggesting it has not yet been widely exploited. Attackers can launch the exploit remotely by crafting requests that alter the prodcode parameter. While the public disclosure has made the attack methodology known, the low EPSS score and absence from KEV mean the risk is moderate but currently low in probability.

Generated by OpenCVE AI on September 15, 2026 at 14:46 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Check for and apply any vendor-provided patch or newer release of the Sales and Inventory System that addresses the prodcode parameter.
  • If no patch is available, modify the application to validate and whitelist the prodcode input, allowing only numeric identifiers.
  • Update the database access code to use prepared statements with parameterized queries, eliminating the ability to inject SQL through the prodcode field.

Generated by OpenCVE AI on September 15, 2026 at 14:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. Impacted is an unknown function of the file /pages/pro_edit1.php. Such manipulation of the argument prodcode leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.
Title itsourcecode Sales and Inventory System pro_edit1.php sql injection
First Time appeared Itsourcecode
Itsourcecode sales And Inventory System
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:itsourcecode:sales_and_inventory_system:*:*:*:*:*:*:*:*
Vendors & Products Itsourcecode
Itsourcecode sales And Inventory System
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Itsourcecode Sales And Inventory System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-16T14:50:51.981Z

Reserved: 2026-09-13T05:26:19.967Z

Link: CVE-2026-90700

cve-icon Vulnrichment

Updated: 2026-09-16T14:50:17.674Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T09:17:02.720

Modified: 2026-09-16T15:18:40.160

Link: CVE-2026-90700

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T15:00:17Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')